| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Jul-22 16:33:42 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\Users\Daniel\Desktop\loader\x64\Release\artSpoofer.pdb
|
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Suspicious | PEiD Signature: | UPolyX V0.1 -> Delikon |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Accesses the WMI:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to RC5 or RC6 Uses known Mersenne Twister constants Microsoft's Cryptography API |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x118 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-Jul-22 16:33:42 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xeb800 |
| SizeOfInitializedData | 0x47bc00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000000E8980 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x56b000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| d3d11.dll |
D3D11CreateDeviceAndSwapChain
|
|---|---|
| D3DCOMPILER_47.dll |
D3DCompile
|
| ole32.dll |
CoInitializeSecurity
CoSetProxyBlanket CoCreateInstance CoUninitialize CoTaskMemFree CoInitializeEx |
| WINHTTP.dll |
WinHttpOpen
WinHttpOpenRequest WinHttpCloseHandle WinHttpReceiveResponse WinHttpSendRequest WinHttpConnect WinHttpReadData WinHttpGetDefaultProxyConfiguration WinHttpGetIEProxyConfigForCurrentUser WinHttpQueryDataAvailable |
| CRYPT32.dll |
CryptProtectData
CryptUnprotectData |
| KERNEL32.dll |
CloseHandle
LocalFree Sleep VirtualFree DeviceIoControl VirtualAlloc GetCurrentThreadId GetModuleHandleA GetCurrentProcessId GetTempPathW GetSystemFirmwareTable GetEnvironmentVariableW MultiByteToWideChar GlobalFree CreateRemoteThreadEx WriteProcessMemory VirtualProtect GetCurrentProcess TerminateProcess GetProcessId DuplicateHandle OpenProcess GetTickCount64 K32GetModuleFileNameExA LoadLibraryA CreateThread VirtualProtectEx VirtualAllocEx ExitProcess ReadProcessMemory GetModuleHandleW CreateRemoteThread GetTickCount OpenThread IsDebuggerPresent WideCharToMultiByte GetFileAttributesExW QueryDosDeviceW GetLogicalDrives WaitForSingleObject CreateToolhelp32Snapshot Process32NextW Process32FirstW QueryFullProcessImageNameW QueryPerformanceCounter GetDriveTypeW GlobalAlloc GlobalLock GlobalUnlock GetLocaleInfoA DeleteFileW GlobalMemoryStatusEx InitOnceComplete SleepConditionVariableSRW AcquireSRWLockExclusive ReleaseSRWLockExclusive CreateFileMappingA UnmapViewOfFile MapViewOfFile HeapFree HeapAlloc CreateFileA GetFileInformationByHandleEx FormatMessageA GetLocaleInfoEx WakeAllConditionVariable SetUnhandledExceptionFilter GetStartupInfoW GetSystemTimeAsFileTime InitializeSListHead GetLastError CreateFileW WriteFile GetFileSizeEx ReadFile FreeLibrary GetProcAddress InitOnceBeginInitialize FindClose FindFirstFileW FindFirstFileExW FindNextFileW GetFinalPathNameByHandleW SetFileInformationByHandle CreateFile2 QueryPerformanceFrequency CreateDirectoryW CheckRemoteDebuggerPresent |
| USER32.dll |
GetCapture
ClientToScreen TrackMouseEvent GetKeyboardLayout GetForegroundWindow LoadCursorW SetCapture SetCursor IsWindowUnicode ReleaseCapture SetCursorPos GetCursorPos OpenClipboard RegisterClassExW EmptyClipboard GetMessageExtraInfo GetKeyState ScreenToClient ShowWindow DispatchMessageW GetSystemMetrics SetWindowRgn SetWindowPos EnumDisplayDevicesA UpdateWindow FindWindowA GetWindowTextLengthA PostQuitMessage GetClientRect FindWindowW TranslateMessage SetLayeredWindowAttributes EnumWindows SetWindowsHookW GetClipboardData SetClipboardData MessageBoxA GetWindowLongW DefWindowProcW CloseClipboard DestroyWindow IsWindowVisible MessageBoxW SetWindowLongA CreateWindowExW PeekMessageW GetWindowTextA UnregisterClassW |
| GDI32.dll |
CreateRoundRectRgn
|
| ADVAPI32.dll |
CryptDestroyHash
RegDeleteValueW RegQueryValueExW QueryServiceStatus CloseServiceHandle OpenSCManagerA ControlService RegOpenKeyExA RegQueryValueExA RegCloseKey RegOpenKeyW RegCreateKeyW RegDeleteTreeW RegSetKeyValueW CryptReleaseContext CryptGetHashParam RegOpenKeyExW CryptHashData CryptCreateHash CryptAcquireContextA GetTokenInformation OpenServiceA OpenProcessToken |
| SHELL32.dll |
SHGetKnownFolderPath
ShellExecuteA |
| OLEAUT32.dll |
SysFreeString
VariantClear SysAllocString VariantInit |
| MSVCP140.dll |
??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z ?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z ??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ ?write@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEBD_J@Z ??7ios_base@std@@QEBA_NXZ ?always_noconv@codecvt_base@std@@QEBA_NXZ ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@I@Z _Query_perf_frequency _Cnd_do_broadcast_at_thread_exit _Query_perf_counter _Thrd_detach ?_Winerror_map@std@@YAHH@Z ?_Random_device@std@@YAIXZ ?_Syserror_map@std@@YAPEBDH@Z ?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ ?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ ?_Fiopen@std@@YAPEAU_iobuf@@PEB_WHH@Z ?_Xbad_alloc@std@@YAXXZ ?_Xlength_error@std@@YAXPEBD@Z ?_Throw_Cpp_error@std@@YAXH@Z _Mtx_lock _Mtx_unlock ?uncaught_exceptions@std@@YAHXZ ?_Xout_of_range@std@@YAXPEBD@Z ?setw@std@@YA?AU?$_Smanip@_J@1@_J@Z ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ ?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ ?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z ?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z ?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@H@Z ?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A ?good@ios_base@std@@QEBA_NXZ ??1_Lockit@std@@QEAA@XZ ??0_Lockit@std@@QEAA@H@Z ?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ ?_Id_cnt@id@locale@std@@0HA |
| ntdll.dll |
NtQuerySystemInformation
RtlInitUnicodeString |
| WS2_32.dll |
htons
setsockopt WSAGetLastError recv htonl connect getsockopt closesocket shutdown WSAStartup inet_ntop send socket |
| WINMM.dll |
mciSendStringW
|
| IMM32.dll |
ImmSetCandidateWindow
ImmSetCompositionWindow ImmReleaseContext ImmGetContext |
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| VCRUNTIME140.dll |
strchr
strrchr longjmp memcpy memmove memset memchr strstr _CxxThrowException __C_specific_handler __current_exception __current_exception_context __intrinsic_setjmp wcsstr memcmp __std_exception_copy __std_exception_destroy __std_terminate |
| api-ms-win-crt-heap-l1-1-0.dll |
malloc
realloc _set_new_mode _callnewh free |
| api-ms-win-crt-stdio-l1-1-0.dll |
fflush
fputc fclose fgetc __p__commode _set_fmode fwrite fgetpos __stdio_common_vsscanf __stdio_common_vsprintf _wfopen __stdio_common_vfprintf fseek __acrt_iob_func ftell ungetc __stdio_common_vswprintf_s _get_stream_buffer_pointers _fseeki64 fread fsetpos setvbuf |
| api-ms-win-crt-utility-l1-1-0.dll |
qsort
rand srand |
| api-ms-win-crt-filesystem-l1-1-0.dll |
_wremove
_lock_file _unlock_file |
| api-ms-win-crt-string-l1-1-0.dll |
strncmp
strcmp strncpy _wcsnicmp strncpy_s _wcsicmp towlower isspace isalnum tolower _stricmp strlen wcslen |
| api-ms-win-crt-time-l1-1-0.dll |
_time64
|
| api-ms-win-crt-runtime-l1-1-0.dll |
_set_app_type
_cexit _get_narrow_winmain_command_line _initterm _initterm_e _exit _crt_atexit _c_exit _register_thread_local_exe_atexit_callback _register_onexit_function _initialize_onexit_table _initialize_narrow_environment _configure_narrow_argv exit _beginthreadex _seh_filter_exe terminate abort |
| api-ms-win-crt-environment-l1-1-0.dll |
_dupenv_s
|
| api-ms-win-crt-convert-l1-1-0.dll |
strtol
|
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| api-ms-win-crt-math-l1-1-0.dll |
cosf
fmodf sinf ceilf acosf floorf sqrtf __setusermatherr |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jul-22 16:33:42 |
| Version | 0.0 |
| SizeofData | 82 |
| AddressOfRawData | 0x4bdb68 |
| PointerToRawData | 0x4bc768 |
| Referenced File | C:\Users\Daniel\Desktop\loader\x64\Release\artSpoofer.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jul-22 16:33:42 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x4bdbbc |
| PointerToRawData | 0x4bc7bc |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jul-22 16:33:42 |
| Version | 0.0 |
| SizeofData | 912 |
| AddressOfRawData | 0x4bdbd0 |
| PointerToRawData | 0x4bc7d0 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jul-22 16:33:42 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x1404bdf80 |
|---|---|
| EndAddressOfRawData | 0x1404bdf88 |
| AddressOfIndex | 0x14055d100 |
| AddressOfCallbacks | 0x1400ede80 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1404d3040 |
| XOR Key | 0x95e9328b |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 22 |
| C objects (35222) | 1 |
| 253 (35721) | 1 |
| C objects (35721) | 10 |
| C++ objects (35721) | 44 |
| ASM objects (35721) | 6 |
| Imports (35721) | 6 |
| C objects (VS2022 Update 1 (17.1.6) compiler 31107) | 26 |
| C++ objects (35222) | 1 |
| Imports (35222) | 35 |
| Total imports | 440 |
| C++ objects (LTCG) (36248) | 32 |
| Resource objects (36248) | 1 |
| Linker (36248) | 1 |
No comments yet.